Whether it's valid or not, there is something that rubs me the wrong way about a security tools company using a real customer/vendor as a marketing campaign. This "story" could have been told without naming, bluntly, their "victim". It would be different if it was some complex, multi-step exploit, but the tone is closer to "look how much Baseten fucked up!". Strix also crossed the line at this point: > Strix decided…
Agreed. I suppose they'd have slightly less credibility by saying "we hacked " but it strikes me as far classier than naming & shaming.
There's no shame here, this was a mistake, probably made by a human, and ultimately corrected. Nobody seems upset by the outcome!